Privacy policy
This is a translation for convenience. In case of any discrepancy, the German version prevails.
This policy describes which personal data we process, for what purpose and on what legal basis. It covers visits to this website and the delivery of our assessment services.
1. Overview
We keep data processing deliberately lean. This website uses no analytics cookies, no advertising tracking and no social media plugins. The website does not load fonts from third parties.
2. Controller
PD on Demand GmbH
Grabenstrasse 15a
6340 Baar
Switzerland
Represented by: Lukas B. von Lindern
Email: info@pd-ondemand.ch
Phone: +41 79 705 27 27
The controller is the natural or legal person that decides on the purposes and means of processing personal data.
3. Applicable law and our Swiss location
We are based in Switzerland, so the Swiss Federal Act on Data Protection applies. Because we offer our services specifically to companies and individuals in the European Economic Area, the GDPR also applies under Art. 3(2) GDPR. We follow whichever standard is stricter.
The European Commission has issued an adequacy decision for Switzerland. Transfers of personal data to Switzerland are therefore permitted without additional safeguards.
4. Your rights
You have the right to access the data we hold about you, to have inaccurate data corrected, to erasure, to restriction of processing, to data portability and to object to processing based on legitimate interests. You can withdraw consent at any time with effect for the future. Processing carried out before the withdrawal remains lawful.
An informal message to info@pd-ondemand.ch is enough for any of these requests.
If you believe we are processing your data unlawfully, you can lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner. In the EEA, the competent authority is the one in your place of residence, your place of work or the place of the alleged infringement.
5. Visiting this website
Server log files
When you open the website, your browser transmits technical data that our host stores in log files. This includes your IP address, the date and time of access, the page requested, the volume of data transferred, the browser type and the operating system.
- Purpose: technical operation, stability and security of the website
- Legal basis: Art. 6(1)(f) GDPR, legitimate interest in secure and reliable operation
- Retention: 90 days, then automatic deletion
Hosting
Hosting provider: GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (GitHub Pages). Server location: GitHub operates a global infrastructure; GitHub states that GitHub.com data is stored by default in the USA and that processing may also take place in other countries. When a GitHub Pages site is visited, the visitor's IP address is logged and stored for security purposes. Further information: GitHub Pages documentation and GitHub Privacy Statement.
Encryption
This website is served exclusively over HTTPS. Your entries are encrypted in transit.
Fonts
The website uses system fonts and does not load web fonts from third parties. There is therefore no connection to third-party font servers.
6. Contact form
If you use the contact form, we process the details you enter in order to handle your enquiry and any follow-up questions.
- Data collected: name, company, email address, optionally phone number, topic and message
- Purpose: handling your enquiry
- Legal basis: Art. 6(1)(b) GDPR where the enquiry relates to a contract or pre-contractual steps. Otherwise Art. 6(1)(f) GDPR, legitimate interest in responding to enquiries
- Retention: until the enquiry is fully handled, then deletion. Statutory retention periods remain unaffected
Form service provider: Formspree, Inc., Austin, Texas, USA (publicly stated company location; Formspree does not publish a complete street address in its official privacy and legal information). Server location: United States; Formspree states that its services are hosted with Amazon Web Services in the United States and that data may also be processed in other countries. Formspree states that it relies on Standard Contractual Clauses for international transfers. Further information: Formspree Privacy Policy and Formspree Security.
7. Scheduling via Calendly
We use Calendly to arrange introductory calls. The provider is Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA.
When you book a slot, Calendly processes the details you provide, in particular your name, email address, chosen time and time zone, and any notes about your enquiry. Data is transferred to the USA in the process.
- Purpose: arranging and managing appointments
- Legal basis: Art. 6(1)(b) GDPR for pre-contractual steps. Where cookies are set or information is stored on your device, additionally Art. 6(1)(a) GDPR and Section 25(1) TDDDG
- Basis for the transfer to the USA: European Commission standard contractual clauses
You can always skip the booking tool and simply email us instead.
8. Contact via WhatsApp
We offer contact via WhatsApp. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland, part of the Meta group.
If you message us on WhatsApp, we process your phone number, your profile name and the content of your messages. Meta additionally processes metadata such as the time and frequency of communication. We have no influence over that processing. A transfer to the USA takes place.
- Purpose: fast and straightforward communication at your request
- Legal basis: Art. 6(1)(a) GDPR. You give consent by actively contacting us on WhatsApp
- Retention: we delete chat histories once the matter is settled, at the latest after 90 days
Please note: do not send confidential content via WhatsApp, in particular no assessment results, no information about individual employees and no candidate data. For anything involving personal data, please use email or our protected channels. If you prefer not to use WhatsApp, email, phone and the contact form work just as well.
9. Processing within our services
This section is not about visiting the website. It covers assessments, debriefings and development programmes, and it is the most important part of this policy for us.
What we process
Basic details of the participant such as name, email address, role and organisation. The answers given in the questionnaire of the respective instrument. The resulting analyses and reports. Notes from the debriefing, where needed for the development plan. The development plan itself.
Roles
In most cases a company commissions us to carry out the work. The division of responsibility between the company and us is agreed in writing before the project starts, including a processing agreement under Art. 28 GDPR or, where applicable, a joint controllership arrangement under Art. 26 GDPR. We tell each participant which arrangement applies before they begin.
Legal basis
Participation in an assessment is based on the voluntary consent of the participant under Art. 6(1)(a) GDPR. We obtain this consent before the assessment starts and it can be withdrawn at any time. In a selection context, Art. 6(1)(b) GDPR may also apply where processing is necessary for the decision on an application. Section 26 BDSG in Germany and equivalent national provisions apply in addition.
Who owns the results
The person assessed always receives the full report first. In the debriefing they learn what the results say and what they do not say. What is passed on to the commissioning company is defined transparently in advance and communicated to the participant before they begin.
Profiling and automated decisions
Psychometric instruments create profiles within the meaning of Art. 4(4) GDPR. However, we make no automated decisions within the meaning of Art. 22 GDPR. A test result never leads to a decision about a person on its own, without human judgement. Every result is interpreted by a certified professional and discussed in conversation. In selection processes we give an assessment, and the commissioning company makes the decision.
Instrument providers
We use the platforms of the respective instrument providers. Depending on the assignment these are Harrison Assessments, PI Company or Hogan Assessments. We state which provider is used before the work begins. Data processing agreements are in place with the providers we use. Where processing takes place outside Switzerland or the EEA, we rely on standard contractual clauses.
Freelance associates
Debriefings may be delivered by certified coaches and psychologists working with us. They are contractually bound to confidentiality and to our data protection requirements, and they only receive the data they need for the conversation in question.
Retention
We keep assessment results and reports for 90 days after the assignment ends, so that follow-up conversations and comparisons over time remain possible. After that we delete them. We delete them earlier on request. Debriefing notes are deleted after 90 days.
10. Sharing with third parties
We do not sell data and we do not pass it on for advertising. Data is only shared with the processors named in this policy, with the commissioning company within the scope agreed in advance, and where we are legally required to do so.
11. Changes
We update this policy when our services, our technology or the legal situation change. The version published on this page is the one that applies.